VYPR

Vendor CVEs

Totolink

All CVEs

1,425 total · sorted by risk
  • CVE-2022-36610HigAug 29, 2022
    risk 0.51cvss 7.8epss 0.00

    TOTOLINK A720R V4.1.5cu.532_B20210610 was discovered to contain a hardcoded password for root at /etc/shadow.sample.

  • CVE-2022-37084HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.00

    TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the sPort parameter at the addEffect function.

  • CVE-2022-37083HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.01

    TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the ip parameter at the function setDiagnosisCfg.

  • CVE-2022-37082HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.01

    TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the host_time parameter at the function NTPSyncWithHost.

  • CVE-2022-37081HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.01

    TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the command parameter at setting/setTracerouteCfg.

  • CVE-2022-37080HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.00

    TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the command parameter at setting/setTracerouteCfg.

  • CVE-2022-37079HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.01

    TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the hostName parameter in the function setOpModeCfg.

  • CVE-2022-37078HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.01

    TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the lang parameter at /setting/setLanguageCfg.

  • CVE-2022-37077HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.00

    TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the pppoeUser parameter.

  • CVE-2022-36455HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.01

    TOTOLink A3600R V4.1.2cu.5182_B20201102 was discovered to contain a command injection vulnerability via the username parameter in /cstecgi.cgi.

  • CVE-2022-37076HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.01

    TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the FileName parameter in the function UploadFirmwareFile.

  • CVE-2022-37075HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.00

    TOTOLink A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ip parameter in the function setDiagnosisCfg.

  • CVE-2022-36488HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.00

    TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a stack overflow via the sPort parameter in the function setIpPortFilterRules.

  • CVE-2022-36487HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.01

    TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the command parameter in the function setTracerouteCfg.

  • CVE-2022-36486HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.01

    TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the FileName parameter in the function UploadFirmwareFile.

  • CVE-2022-36485HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.01

    TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the hostName parameter in the function setOpModeCfg.

  • CVE-2022-36484HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.00

    TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a stack overflow via the function setDiagnosisCfg.

  • CVE-2022-36483HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.00

    TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a stack overflow via the pppoeUser parameter.

  • CVE-2022-36482HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.01

    TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the lang parameter in the function setLanguageCfg.

  • CVE-2022-36481HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.01

    TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the ip parameter in the function setDiagnosisCfg.

  • CVE-2022-36480HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.00

    TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a stack overflow via the command parameter in the function setTracerouteCfg.

  • CVE-2022-36479HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.01

    TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the host_time parameter in the function NTPSyncWithHost.

  • CVE-2022-36466HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.00

    TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a stack overflow via the ip parameter in the function setDiagnosisCfg.

  • CVE-2022-36465HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.00

    TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a stack overflow via the pppoeUser parameter.

  • CVE-2022-36464HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.00

    TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a stack overflow via the sPort parameter in the function setIpPortFilterRules.

  • CVE-2022-36463HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.00

    TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a stack overflow via the command parameter in the function setTracerouteCfg.

  • CVE-2022-36462HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.00

    TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a stack overflow via the lang parameter in the function setLanguageCfg.

  • CVE-2022-36461HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.01

    TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a command injection vulnerability via the hostName parameter in the function setOpModeCfg.

  • CVE-2022-36460HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.01

    TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a command injection vulnerability via the FileName parameter in the function UploadFirmwareFile.

  • CVE-2022-36459HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.01

    TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a command injection vulnerability via the host_time parameter in the function NTPSyncWithHost.

  • CVE-2022-36458HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.01

    TOTOLINK A3700R V9.1.2u.6134_B20201202 was discovered to contain a command injection vulnerability via the command parameter in the function setTracerouteCfg.

  • CVE-2022-36456HigAug 25, 2022
    risk 0.51cvss 7.8epss 0.01

    TOTOLink A720R V4.1.5cu.532_B20210610 was discovered to contain a command injection vulnerability via the username parameter in /cstecgi.cgi.

  • CVE-2024-34217HigMay 14, 2024
    risk 0.50cvss 7.7epss 0.01

    TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the addWlProfileClientMode function.

  • CVE-2024-28640HigMar 16, 2024
    risk 0.50cvss 7.5epss 0.14

    Buffer Overflow vulnerability in TOTOLink X5000R V9.1.0u.6118-B20201102 and A7000R V9.1.0u.6115-B20201022 allows a remote attacker to cause a denial of service (D0S) via the command field.

  • CVE-2021-35325HigAug 5, 2021
    risk 0.50cvss 7.5epss 0.13

    A stack overflow in the checkLoginUser function of TOTOLINK A720R A720R_Firmware v4.1.5cu.470_B20200911 allows attackers to cause a denial of service (DOS).

  • CVE-2026-51768HigSep 1, 2026
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the setElinkQosConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to modify privileged QoS policy on the master device via sending a crafted MQTT message to the cs_broker component.

  • CVE-2026-51766HigSep 1, 2026
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the setDevReboot function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reboot the local device and, on a master, fan out reboot commands to mesh slaves via sending a crafted MQTT message to the cs_broker component.

  • CVE-2026-51735HigAug 31, 2026
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the showSyslog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to retrieve recent system logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51719HigAug 31, 2026
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the delUrlFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove URL filtering rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51716HigAug 31, 2026
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the delPortForwardRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to delete port-forwarding rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51673HigAug 31, 2026
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the setNtpCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter time synchronization settings via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51671HigAug 31, 2026
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the getCloudDownloadStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain cloud firmware download state information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51668HigAug 31, 2026
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the setLanguageCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to modify language configuration via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51662HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the getCloudSrvCheckStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain cloud firmware check status information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51659HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the getUrlFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain DMZ configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51658HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the getDmzCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain DMZ configuration information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51650HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the getRemoteCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain remote-management enablement and port information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51648HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the getWanInfo function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain WAN information returned by the endpoint via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51647HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the getCrpcCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain cloud remote-control status and URL information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51644HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the getCrpcConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain cloud remote-control status and URL information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Page 19 of 29